PC bloqué security protection

Bonjour,

j ai un pc portable acer sous vista.

J ai attrapé sécurity protection. J'ai essayé les manips qui sont recommandées sur ce forum mais rien a faire :quand je lance rogue killer ou malware byte ces programmes ne vont pas au bout et ensuite impossible de les relancer (sur l'icone à été rajouté un petit signe (2 tetes) et le programme me dit qu'il ne trouve pas l'emplacement)

Merci de m aider
Cordialement

44 réponses

Résumé de la discussion

Un utilisateur Acer sous Windows Vista est confronté à une infection Security Protection, et RogueKiller et Malwarebytes ne démarrent plus, affichant des erreurs d’emplacement et d’exécution. Des solutions proposées incluent l’exécution de CFScript via ComboFix et l’utilisation d’USBFix pour nettoyer les éléments résiduels et générer des rapports utiles pour le diagnostic. Le rapport ComboFix identifie des programmes et services indésirables dans les démarrages et le registre, ainsi que des composants modifiés du navigateur, nécessitant des suppressions ciblées. En cas de persistance, certaines mesures recommandées impliquent la vérification des fichiers et clés bloqués, la désactivation temporaire des protections en temps réel et une nouvelle passe de nettoyage avec prudence.

Bobot (l’IA à votre service)
  1. Bonjour

    Te casse pas la tete je reformate.
    Merci de ton aide précieuse je pense que c'est exactement ca l'esprit du net.
    Une derniere question : pense tu que avg free est un bon anti virus?
    Vraiment merci pour ton aide
    Amitiés
    0
    1. J ai réessayé ce matin j ai le meme message (en mode normal et en mode sans echec)
      0
      1. il n y a rien dans le lecteur cd ou card et pas de disk externe
        0
        1. je comprends pas.....

          enleve les trucs que tu as dans les ports usb si presents ainsi que cd dans le lecteur ou sdcard , ou disque dur externe
          0
          1. erreur sur le message d avant : c'est line 17914
            0
            1. bonjour

              je lance pre scan et a la section suppression mountpoint2 une fenetre autoit error s ouvre:
              line 17715 (file c:\user\breton _contacts\desktop\pre scan.exe):
              error:subscript used with non array variable

              je l ai retelechargé plusieur fois meme resultat et essayé dans les 2 modes :sans echec et normal (a noter si je telecharge en mode normal il ne va pas au bout)
              0
              1. excuse moi je travaille de nuit et je pars au boulot
                je continue demain donne moi la marche a suivre

                merci beaucoup
                0
                1. quand je lance l exe ou le pif il reste bloqués sur la fenetre prescan :suppression mountpoints2 et je n'ai plus d activité disque comme tout a l heure
                  0
                  1. ah voila là pre_scan devrait passer
                    0
                    1. voici le rapport

                      ComboFix 11-09-08.03 - breton 08/09/2011 19:22:28.4.2 - x86
                      Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2045.1055 [GMT 2:00]
                      Lancé depuis: c:\users\breton\Contacts\Desktop\eddie.exe
                      Commutateurs utilisés :: c:\users\breton\Contacts\Desktop\CFScript.txt
                      SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                      .
                      .
                      ((((((((((((((((((((((((((((( Fichiers créés du 2011-08-08 au 2011-09-08 ))))))))))))))))))))))))))))))))))))
                      .
                      .
                      2011-09-08 17:27 . 2011-09-08 17:29 -------- d-----w- c:\users\breton\AppData\Local\temp
                      2011-09-08 17:27 . 2011-09-08 17:27 -------- d-----w- c:\users\Default\AppData\Local\temp
                      2011-09-08 14:08 . 2011-09-08 14:12 -------- d-----w- C:\UsbFix
                      2011-09-08 14:00 . 2011-09-08 14:01 -------- d-----w- C:\Kill'em
                      2011-09-07 15:57 . 2008-01-19 05:49 54784 ----a-w- c:\windows\system32\drivers\i8042prt.sys
                      2011-09-07 15:53 . 2011-09-07 16:27 -------- d-----w- C:\eddie
                      2011-09-07 07:48 . 2011-09-07 07:48 -------- d-----w- C:\TDSSKiller
                      2011-09-05 10:46 . 2011-02-15 17:16 86016 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\msimg32.dll
                      2011-09-05 10:34 . 2011-08-16 06:48 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E028A9D-6076-4A07-8C9E-4FA7E73CBED3}\mpengine.dll
                      2011-09-05 10:34 . 2011-09-05 10:37 -------- d-----w- C:\ZHP
                      2011-09-05 10:34 . 2011-09-06 10:51 -------- d-----w- c:\program files\ZHPDiag
                      2011-08-30 18:25 . 2011-08-30 18:25 -------- d-----w- c:\users\breton\AppData\Roaming\Malwarebytes
                      2011-08-30 18:25 . 2011-08-30 18:25 -------- d-----w- c:\programdata\Malwarebytes
                      2011-08-30 18:15 . 2011-08-12 06:19 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
                      2011-08-30 18:15 . 2011-08-12 06:19 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
                      2011-08-30 18:15 . 2011-08-12 06:19 785368 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
                      2011-08-30 18:15 . 2011-08-12 06:19 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
                      2011-08-30 18:15 . 2011-08-12 06:19 1846232 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
                      2011-08-30 18:15 . 2011-08-12 06:19 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
                      2011-08-30 18:15 . 2011-08-12 03:15 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
                      2011-08-30 18:15 . 2011-08-12 03:15 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
                      2011-08-30 17:50 . 2011-08-30 17:50 -------- d--h--w- c:\programdata\Common Files
                      2011-08-30 17:43 . 2011-08-30 17:50 -------- d-----w- c:\programdata\MFAData
                      2011-08-29 22:52 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
                      2011-08-29 22:52 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
                      .
                      .
                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2011-09-08 14:12 . 2011-09-08 14:12 5132 ----a-w- C:\UsbFix_Upload_Me_PC-DE-BRETON.zip
                      2011-08-12 06:19 . 2011-08-30 18:15 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
                      .
                      .
                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4
                      .
                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
                      2009-10-15 08:53 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
                      .
                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                      "{1c99b848-84cb-4ce4-8cd8-ed5719484d9f}"= "mscoree.dll" [2009-11-08 297808]
                      .
                      [HKEY_CLASSES_ROOT\clsid\{1c99b848-84cb-4ce4-8cd8-ed5719484d9f}]
                      [HKEY_CLASSES_ROOT\UnifiedToolbar.UnifiedToolbar]
                      .
                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
                      "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                      .
                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]
                      "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-25 86016]
                      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-25 8470528]
                      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-25 81920]
                      "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-07-21 2048352]
                      "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-09-19 615696]
                      "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-08-26 236016]
                      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
                      .
                      c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                      Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-8-10 535336]
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                      "EnableLUA"= 0 (0x0)
                      "EnableUIADesktopToggle"= 0 (0x0)
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                      "aux"=wdmaud.drv
                      .
                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                      @="Driver"
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
                      2010-09-16 20:04 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
                      2009-12-03 09:12 976320 ----a-w- c:\program files\Epson Software\Event Manager\EEventManager.exe
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
                      2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                      "DisableMonitoring"=dword:00000001
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                      "DisableMonitoring"=dword:00000001
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                      "DisableMonitoring"=dword:00000001
                      .
                      R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
                      R2 AGCoreService;AG Core Services;c:\program files\AGI\core\4.2.0.10754\AGCoreService.exe [2011-09-05 20480]
                      R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [x]
                      R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2009-03-30 66368]
                      R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [x]
                      R2 ServiceSFRABCD;Service SFR Gestionnaire Connexion;c:\program files\SFR\Gestionnaire de Connexion SFR\SFRABCDService.exe [x]
                      R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2008-10-29 7680]
                      R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
                      R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
                      R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2008-10-13 110080]
                      R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [2008-10-15 104960]
                      S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
                      S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-02 13560]
                      S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-06-05 179712]
                      S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2007-03-07 32256]
                      .
                      .
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
                      .
                      .
                      ------- Examen supplémentaire -------
                      .
                      uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
                      uInternet Settings,ProxyOverride = *.local
                      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                      TCP: DhcpNameServer = 192.168.1.1
                      DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                      FF - ProfilePath - c:\users\breton\AppData\Roaming\Mozilla\Firefox\Profiles\v3g834g7.default\
                      FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
                      FF - prefs.js: browser.search.selectedEngine - Yahoo
                      FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
                      FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&q=
                      .
                      - - - - ORPHELINS SUPPRIMES - - - -
                      .
                      HKCU-Run-MsnMsgr - ~c:\program files\Windows Live\Messenger\MsnMsgr.Exe
                      HKCU-Run-Connexion SFR 9props.exe - c:\program files\SFR\Kit\9props .exe
                      .
                      .
                      .
                      **************************************************************************
                      .
                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2011-09-08 19:29
                      Windows 6.0.6002 Service Pack 2 NTFS
                      .
                      Recherche de processus cachés ...
                      .
                      Recherche d'éléments en démarrage automatique cachés ...
                      .
                      Recherche de fichiers cachés ...
                      .
                      Scan terminé avec succès
                      Fichiers cachés: 0
                      .
                      **************************************************************************
                      .
                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
                      "ImagePath"="\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
                      .
                      --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                      .
                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                      @Denied: (A) (Users)
                      @Denied: (A) (Everyone)
                      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                      "BlindDial"=dword:00000000
                      .
                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
                      @Denied: (A) (Users)
                      @Denied: (A) (Everyone)
                      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                      "BlindDial"=dword:00000000
                      .
                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
                      @Denied: (A) (Users)
                      @Denied: (A) (Everyone)
                      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                      "BlindDial"=dword:00000000
                      .
                      ------------------------ Autres processus actifs ------------------------
                      .
                      c:\program files\CyberLink\Shared Files\RichVideo.exe
                      c:\windows\system32\conime.exe
                      c:\windows\RtHDVCpl.exe
                      c:\windows\System32\rundll32.exe
                      c:\program files\AVG\AVG8\avgtray.exe
                      c:\windows\System32\rundll32.exe
                      c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                      c:\windows\system32\DRIVERS\xaudio.exe
                      c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                      c:\windows\ehome\ehmsas.exe
                      c:\acer\Empowering Technology\ENET\ENMTRAY.EXE
                      c:\program files\Windows Media Player\wmpnscfg.exe
                      c:\program files\Windows Media Player\wmpnetwk.exe
                      c:\acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                      c:\acer\Empowering Technology\eRecovery\ERAGENT.EXE
                      c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
                      .
                      **************************************************************************
                      .
                      Heure de fin: 2011-09-08 19:35:43 - La machine a redémarré
                      ComboFix-quarantined-files.txt 2011-09-08 17:35
                      ComboFix2.txt 2011-09-08 16:15
                      ComboFix3.txt 2011-09-07 18:42
                      ComboFix4.txt 2011-09-07 16:27
                      .
                      Avant-CF: 7 114 444 800 octets libres
                      Après-CF: 7 068 745 728 octets libres
                      .
                      - - End Of File - - D4540DCA63527790E6DD366D849379C6
                      0

                      1. __________________________________________________
                        =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
                        =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
                        ----------------------------------------------------------------------------


                        Toujours avec toutes les protections désactivées, fais ceci :

                        ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                        ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                        ----------------------------------------------------------
                        KillAll::
                        
                        Registry::
                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] 
                        "{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"=-
                        [-HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]  
                        [-HKEY_CLASSES_ROOT\agihelper.AGUtils]      
                        [-HKEY_CLASSES_ROOT\TypeLib\{647B16D8-AD7B-4983-82D7-82A270FC9E6D}]      
                        [-HKEY_CLASSES_ROOT\agcutils.AGSearchHook]      
                        [-HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Explorer\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
                        "Connexion SFR 9props.exe"="c:\program files\SFR\Kit\9props.exe"
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "LManager"=-
                        "KiweeHook"=-
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 
                        ""=-     
                        [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
                        
                        RenV::
                        c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
                        c:\program files\Kiwee Toolbar\3.3\kwtbaim .exe
                        c:\program files\AVG\AVG8\avgtray .exe 
                        c:\program files\Common Files\Java\Java Update\jusched .exe  
                        c:\program files\Launch Manager\LManager .exe   
                        
                        Firefox::
                        FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
                        FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&q= 
                        
                        

                        ------------------------------------------------------------------

                        ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
                        ▶ Quitte le Bloc Notes

                        ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

                        ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                        ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                        ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                        0
                        1. voici le rapport

                          ComboFix 11-09-08.03 - breton 08/09/2011 18:08:35.3.2 - x86
                          Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2045.1169 [GMT 2:00]
                          Lancé depuis: c:\users\breton\Contacts\Desktop\eddie.exe
                          SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                          .
                          .
                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          c:\progra~1\AVG\AVG8\avgtray.exe
                          c:\progra~1\LAUNCH~1\LManager.exe
                          c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                          c:\program files\Kiwee Toolbar\3.3\kwtbaim.exe
                          .
                          [code] <pre>
                          c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe --->c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                          c:\program files\Kiwee Toolbar\3.3\kwtbaim .exe --->c:\program files\Kiwee Toolbar\3.3\kwtbaim.exe
                          </pre> /code
                          .
                          .
                          ((((((((((((((((((((((((((((( Fichiers créés du 2011-08-08 au 2011-09-08 ))))))))))))))))))))))))))))))))))))
                          .
                          .
                          2011-09-08 16:13 . 2011-09-08 16:14 -------- d-----w- c:\users\breton\AppData\Local\temp
                          2011-09-08 16:13 . 2011-09-08 16:13 -------- d-----w- c:\users\Default\AppData\Local\temp
                          2011-09-08 14:08 . 2011-09-08 14:12 -------- d-----w- C:\UsbFix
                          2011-09-08 14:00 . 2011-09-08 14:01 -------- d-----w- C:\Kill'em
                          2011-09-07 15:57 . 2008-01-19 05:49 54784 ----a-w- c:\windows\system32\drivers\i8042prt.sys
                          2011-09-07 15:53 . 2011-09-07 16:27 -------- d-----w- C:\eddie
                          2011-09-07 07:48 . 2011-09-07 07:48 -------- d-----w- C:\TDSSKiller
                          2011-09-05 10:46 . 2011-02-15 17:16 86016 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\msimg32.dll
                          2011-09-05 10:34 . 2011-08-16 06:48 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E028A9D-6076-4A07-8C9E-4FA7E73CBED3}\mpengine.dll
                          2011-09-05 10:34 . 2011-09-05 10:37 -------- d-----w- C:\ZHP
                          2011-09-05 10:34 . 2011-09-06 10:51 -------- d-----w- c:\program files\ZHPDiag
                          2011-08-30 18:25 . 2011-08-30 18:25 -------- d-----w- c:\users\breton\AppData\Roaming\Malwarebytes
                          2011-08-30 18:25 . 2011-08-30 18:25 -------- d-----w- c:\programdata\Malwarebytes
                          2011-08-30 18:15 . 2011-08-12 06:19 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
                          2011-08-30 18:15 . 2011-08-12 06:19 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
                          2011-08-30 18:15 . 2011-08-12 06:19 785368 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
                          2011-08-30 18:15 . 2011-08-12 06:19 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
                          2011-08-30 18:15 . 2011-08-12 06:19 1846232 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
                          2011-08-30 18:15 . 2011-08-12 06:19 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
                          2011-08-30 18:15 . 2011-08-12 03:15 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
                          2011-08-30 18:15 . 2011-08-12 03:15 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
                          2011-08-30 17:50 . 2011-08-30 17:50 -------- d--h--w- c:\programdata\Common Files
                          2011-08-30 17:43 . 2011-08-30 17:50 -------- d-----w- c:\programdata\MFAData
                          2011-08-29 22:52 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
                          2011-08-29 22:52 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
                          .
                          .
                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2011-09-08 14:12 . 2011-09-08 14:12 5132 ----a-w- C:\UsbFix_Upload_Me_PC-DE-BRETON.zip
                          2011-08-12 06:19 . 2011-08-30 18:15 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
                          .
                          [code]<pre>
                          c:\program files\AVG\AVG8\avgtray .exe
                          c:\program files\Common Files\Java\Java Update\jusched .exe
                          c:\program files\Launch Manager\LManager .exe
                          </pre>/code
                          .
                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4
                          .
                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                          "{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "mscoree.dll" [2009-11-08 297808]
                          .
                          [HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
                          [HKEY_CLASSES_ROOT\agihelper.AGUtils]
                          [HKEY_CLASSES_ROOT\TypeLib\{647B16D8-AD7B-4983-82D7-82A270FC9E6D}]
                          [HKEY_CLASSES_ROOT\agcutils.AGSearchHook]
                          .
                          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
                          2009-11-08 08:55 297808 ----a-w- c:\windows\System32\mscoree.dll
                          .
                          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
                          2009-10-15 08:53 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
                          .
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                          "{1c99b848-84cb-4ce4-8cd8-ed5719484d9f}"= "mscoree.dll" [2009-11-08 297808]
                          .
                          [HKEY_CLASSES_ROOT\clsid\{1c99b848-84cb-4ce4-8cd8-ed5719484d9f}]
                          [HKEY_CLASSES_ROOT\UnifiedToolbar.UnifiedToolbar]
                          .
                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
                          "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                          "MsnMsgr"="~c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [N/A]
                          "Connexion SFR 9props.exe"="c:\program files\SFR\Kit\9props .exe" [N/A]
                          .
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]
                          "LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [N/A]
                          "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-25 86016]
                          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-25 8470528]
                          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-25 81920]
                          "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [N/A]
                          "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-09-19 615696]
                          "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-08-26 236016]
                          "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-07-11 39940]
                          "KiweeHook"="c:\program files\Kiwee Toolbar\3.3\kwtbaim.exe" [2011-02-15 53248]
                          .
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                          "<NO NAME>"="" [N/A]
                          .
                          c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                          Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-8-10 535336]
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                          "EnableLUA"= 0 (0x0)
                          "EnableUIADesktopToggle"= 0 (0x0)
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                          "aux"=wdmaud.drv
                          .
                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                          @="Driver"
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
                          2010-09-16 20:04 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
                          2009-12-03 09:12 976320 ----a-w- c:\program files\Epson Software\Event Manager\EEventManager.exe
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
                          c:\program files\SweetIM\Messenger\SweetIM.exe [N/A]
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
                          2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                          "DisableMonitoring"=dword:00000001
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                          "DisableMonitoring"=dword:00000001
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                          "DisableMonitoring"=dword:00000001
                          .
                          R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
                          R2 AGCoreService;AG Core Services;c:\program files\AGI\core\4.2.0.10754\AGCoreService.exe [2011-09-05 20480]
                          R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [x]
                          R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2009-03-30 66368]
                          R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [x]
                          R2 ServiceSFRABCD;Service SFR Gestionnaire Connexion;c:\program files\SFR\Gestionnaire de Connexion SFR\SFRABCDService.exe [x]
                          R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2008-10-29 7680]
                          R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
                          R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
                          R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2008-10-13 110080]
                          R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [2008-10-15 104960]
                          S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
                          S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-02 13560]
                          S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-06-05 179712]
                          S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2007-03-07 32256]
                          .
                          .
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                          LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
                          .
                          Contenu du dossier 'Tâches planifiées'
                          .
                          .
                          ------- Examen supplémentaire -------
                          .
                          uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
                          uInternet Settings,ProxyOverride = *.local
                          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                          TCP: DhcpNameServer = 192.168.1.1
                          DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                          FF - ProfilePath - c:\users\breton\AppData\Roaming\Mozilla\Firefox\Profiles\v3g834g7.default\
                          FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
                          FF - prefs.js: browser.search.selectedEngine - Yahoo
                          FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
                          FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&q=
                          .
                          .
                          **************************************************************************
                          .
                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2011-09-08 18:14
                          Windows 6.0.6002 Service Pack 2 NTFS
                          .
                          Recherche de processus cachés ...
                          .
                          Recherche d'éléments en démarrage automatique cachés ...
                          .
                          Recherche de fichiers cachés ...
                          .
                          Scan terminé avec succès
                          Fichiers cachés: 0
                          .
                          **************************************************************************
                          .
                          [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
                          "ImagePath"="\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
                          .
                          --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                          .
                          [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                          @Denied: (A) (Users)
                          @Denied: (A) (Everyone)
                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                          "BlindDial"=dword:00000000
                          .
                          [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
                          @Denied: (A) (Users)
                          @Denied: (A) (Everyone)
                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                          "BlindDial"=dword:00000000
                          .
                          [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
                          @Denied: (A) (Users)
                          @Denied: (A) (Everyone)
                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                          "BlindDial"=dword:00000000
                          .
                          Heure de fin: 2011-09-08 18:15:39
                          ComboFix-quarantined-files.txt 2011-09-08 16:15
                          ComboFix2.txt 2011-09-07 18:42
                          ComboFix3.txt 2011-09-07 16:27
                          .
                          Avant-CF: 7 240 478 720 octets libres
                          Après-CF: 7 204 691 968 octets libres
                          .
                          - - End Of File - - 85B29AC00A4E42FB3306E452F6969C81
                          0
                          1. voila le rapport

                            ############################## | UsbFix 7.058 | [Suppression]

                            Utilisateur: breton (Administrateur) # PC-DE-BRETON [Acer Aspire 7720]
                            Mis à jour le 24/08/2011 par El Desaparecido
                            Lancé à 16:09:01 | 08/09/2011
                            Site Web: http://www.teamxscript.org
                            Submit your sample: http://www.teamxscript.org/Upload.php
                            Contact: TeamXscript.ElDesaparecido@gmail.com

                            CPU: Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz
                            CPU 2: Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz
                            Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
                            Internet Explorer 8.0.6001.19120

                            Pare-feu Windows: Activé
                            Antivirus: AVG Anti-Virus Free 8.0 [Enabled | Updated]
                            RAM -> 2045 Mo
                            C:\ (%systemdrive%) -> Disque fixe # 70 Go (7 Go libre(s) - 10%) [ACER] # NTFS
                            D:\ -> Disque fixe # 70 Go (63 Go libre(s) - 91%) [DATA] # NTFS
                            E:\ -> CD-ROM
                            F:\ -> Disque amovible # 2 Go (1 Go libre(s) - 54%) [] # FAT

                            ################## | Éléments infectieux |

                            Supprimé! C:\$RECYCLE.BIN\S-1-5-21-3443625851-3002216365-3998361680-1000
                            Supprimé! D:\$RECYCLE.BIN\S-1-5-21-3443625851-3002216365-3998361680-1000
                            Supprimé! D:\$RECYCLE.BIN\S-1-5-21-3443625851-3002216365-3998361680-500

                            ################## | Registre |

                            Non supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{22116563-108C-42c0-A7CE-60161B75E508}
                            Non supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{810401e2-dde0-454e-b0e2-aa89c9e5967c}
                            Non supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}
                            Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
                            Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

                            ################## | Mountpoints2 |

                            ################## | Listing |

                            [16/04/2011 - 21:58:42 | D ] C:\$AVG8.VAULT$
                            [08/09/2011 - 16:10:55 | D ] C:\$RECYCLE.BIN
                            [22/03/2008 - 19:45:18 | D ] C:\Acer
                            [18/09/2006 - 23:43:36 | N | 24] C:\autoexec.bat
                            [10/08/2007 - 16:40:27 | D ] C:\Book
                            [25/04/2010 - 17:11:37 | D ] C:\Boot
                            [11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
                            [07/09/2011 - 20:42:15 | N | 26501] C:\ComboFix.txt
                            [18/09/2006 - 23:43:37 | N | 10] C:\config.sys
                            [02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
                            [02/12/2007 - 23:49:20 | D ] C:\DRV
                            [07/09/2011 - 18:27:44 | D ] C:\eddie
                            [07/09/2011 - 20:42:18 | D ] C:\eddie17005e
                            [08/09/2011 - 15:50:46 | ASH | 2145452032] C:\hiberfil.sys
                            [10/08/2007 - 08:25:09 | D ] C:\Intel
                            [19/09/2009 - 11:49:27 | N | 0] C:\IO.SYS
                            [08/09/2011 - 16:01:07 | D ] C:\Kill'em
                            [29/11/2006 - 17:35:22 | N | 512] C:\MDR.iss
                            [19/09/2009 - 11:49:27 | N | 0] C:\MSDOS.SYS
                            [10/08/2007 - 09:52:33 | RD ] C:\MSOCache
                            [29/02/2004 - 17:44:34 | N | 52576] C:\orange.bmp
                            [08/09/2011 - 15:50:44 | ASH | 2459246592] C:\pagefile.sys
                            [24/10/2008 - 19:59:48 | D ] C:\PerfLogs
                            [08/09/2011 - 16:00:55 | N | 550704] C:\Pre_Scan.txt
                            [08/09/2011 - 10:19:53 | D ] C:\Program Files
                            [07/09/2011 - 20:32:35 | D ] C:\ProgramData
                            [07/09/2011 - 20:42:18 | D ] C:\Qoobox
                            [12/12/2008 - 22:19:12 | N | 200] C:\sqmdata00.sqm
                            [13/12/2008 - 17:36:17 | N | 200] C:\sqmdata01.sqm
                            [13/12/2008 - 17:44:38 | N | 200] C:\sqmdata02.sqm
                            [05/01/2009 - 00:43:38 | N | 232] C:\sqmdata03.sqm
                            [05/01/2009 - 00:52:04 | N | 232] C:\sqmdata04.sqm
                            [05/01/2009 - 19:11:41 | N | 232] C:\sqmdata05.sqm
                            [05/01/2009 - 21:09:46 | N | 232] C:\sqmdata06.sqm
                            [12/12/2008 - 22:19:12 | N | 200] C:\sqmnoopt00.sqm
                            [13/12/2008 - 17:36:17 | N | 200] C:\sqmnoopt01.sqm
                            [13/12/2008 - 17:44:38 | N | 200] C:\sqmnoopt02.sqm
                            [05/01/2009 - 00:43:38 | N | 244] C:\sqmnoopt03.sqm
                            [05/01/2009 - 00:52:04 | N | 244] C:\sqmnoopt04.sqm
                            [05/01/2009 - 19:11:41 | N | 244] C:\sqmnoopt05.sqm
                            [05/01/2009 - 21:09:46 | N | 244] C:\sqmnoopt06.sqm
                            [08/09/2011 - 03:00:30 | SHD ] C:\System Volume Information
                            [07/09/2011 - 09:48:44 | D ] C:\TDSSKiller
                            [08/09/2011 - 16:10:55 | D ] C:\UsbFix
                            [08/09/2011 - 16:09:06 | A | 4015] C:\UsbFix.txt
                            [27/07/2008 - 09:17:17 | D ] C:\Users
                            [08/09/2011 - 14:10:25 | D ] C:\Windows
                            [05/09/2011 - 12:37:15 | D ] C:\ZHP
                            [08/09/2011 - 16:10:55 | D ] D:\$RECYCLE.BIN
                            [23/01/2011 - 17:34:10 | D ] D:\7zip7
                            [06/09/2011 - 13:05:38 | D ] D:\Advanced SystemCare 4
                            [25/07/2010 - 01:21:28 | N | 1849] D:\CDVidéo.cdm
                            [30/08/2009 - 00:47:27 | N | 1194931] D:\dossier FRED.zip
                            [24/08/2010 - 01:10:46 | D ] D:\erData
                            [29/10/2010 - 23:32:04 | D ] D:\Incomplete
                            [10/07/2011 - 22:43:04 | D ] D:\NAVIGON
                            [18/09/2010 - 23:53:19 | D ] D:\pictures
                            [02/12/2007 - 13:58:00 | SHD ] D:\System Volume Information
                            [25/04/2010 - 17:19:23 | D ] D:\VACANCES 2009

                            ################## | Vaccin |

                            C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
                            D:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

                            ################## | Upload |

                            Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-BRETON.zip
                            http://www.teamxscript.org/Upload.php
                            Merci de votre contribution.

                            ################## | E.O.F |
                            0
                            1. inscris-toi sur commentcamarche
                              0
                              1. si je colle le dossier dans la fenetre (ici) quand je fais envoyer le site me marque en rouge titre du message non renseigné
                                0
                                1. ▶ Télécharge ici : USBFIX sur ton bureau

                                  branche tous tes periphériques sans les ouvrir

                                  /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                                  si tu as XP => double clique
                                  si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                                  sur l'icône Usbfix située sur ton Bureau.
                                  Sur la page, clique sur le bouton :

                                  ▶ choisi l option Suppression

                                  ▶ UsbFix scannera ton pc , laisse travailler l outil.

                                  ▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                                  ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  0
                                  1. j ai retelechargé le exe et le pif quand je l'ai lance il reste bloqués sur la fenetre prescan :suppression mountpoints2 et je n'ai plus d activité disque
                                    0
                                    • 1
                                    • 2
                                    • 3